@demystify/tools-runner
v0.1.0
Published
Bring-Your-Own-Cloud runner — self-host Demystify tool engines; your data never leaves your machine
Maintainers
Readme
@demystify/tools-runner — Bring Your Own Cloud
Self-host the Demystify tool engines. The browser tools call your runner; results return to your browser. Demystify never sees your data — it only ships this open code.
Run it
# Docker (recommended)
docker run -p 8787:8787 demystify/tools-runner
# or from source
pnpm --filter @demystify/tools-runner build
PORT=8787 CORS_ORIGIN=https://demystifysystem.com pnpm --filter @demystify/tools-runner startThen paste http://localhost:8787 (or your deployed URL) into Settings → Bring your own
cloud → Runner URL on the tools site. Heavy/native tools will route to your runner.
API
| Method | Path | Body | Returns |
|---|---|---|---|
| GET | /health | — | { ok, tools } |
| GET | /v1 | — | { tools: string[] } |
| POST | /v1/{tool} | the tool's JSON input | { tool, result } or a typed error |
Every tool is resolved through the shared engine-binding manifest
(@demystify/tools-engines/api), so its input is validated by the exact same zod schema the
browser and REST API use. The base image runs every pure and isomorphic-bytes tool
(text, data, dev, finance, PDF via pdf-lib, spreadsheets) with no system dependencies.
Heavy tools (later image variant)
Office conversion, PDF/A, native video encode and LaTeX need system binaries (LibreOffice, Ghostscript, full FFmpeg, TeX Live). Those ship in a larger image tag and are legal to run because you self-host — copyleft (AGPL/GPL) is satisfied when you run the open container.
Privacy
The runner never logs request input or output — only a startup line. Set CORS_ORIGIN
to your tools origin to restrict who may call it. Run it behind your own auth/network if you
deploy it publicly.
